CVE-2026-77001

Published Aug 22, 2026

Last updated a day ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-77001 describes an unauthenticated authentication bypass vulnerability found in the "Social Login & Sharing buttons with Analytics By SoClever" WordPress plugin, specifically affecting versions up to and including 1.2.0. This flaw stems from the plugin's failure to perform authentication, authorization, or nonce checks within one of its publicly accessible login handlers. As a result, an unauthenticated attacker can exploit this vulnerability to obtain a valid session as any existing user on the WordPress site. This includes the ability to gain a session as an administrator, potentially without needing to know any account credentials.

Description
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators. In the default case a session as the site's original administrator account is obtained without needing to know any account details at all.
Source
contact@wpscan.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-287

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.